This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Offensive & Pentesting
β No known CVEs patched
This release patches 1 known CVE
Topics
aws
azure
cis-benchmark
cloud
cloudsecurity
compliance
+12 more
cspm
security
forensics
gcp
gdpr
hardening
iam
multi-cloud
python
security-audit
security-hardening
security-tools
Affected surfaces
auth
Summary
AI summaryUpdates π Security, π Fixed, and API across a mixed release.
Full changelog
API
π Security
- SAML logins now link to an existing account only when the asserted email domain matches the ACS endpoint and the user is already a member of that domain's tenant, fixing a cross-tenant account takeover (GHSA-h8m9-jgf8-vwvp) bf3b5c2ba713e533014927141b64948c82c8f32e
SDK
π Fixed
- CLI compliance summary tables no longer undercount findings mapped to multiple sections nor double-count a single finding mapped to several requirements within the same group/split, and the Provider column no longer leaks a value from another framework (#11567)
Security Fixes
- GHSA-h8m9-jgf8-vwvp β SAML logins enforce email domain match and tenant membership, fixing crossβtenant account takeover
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Prowler
Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.
Beta — feedback welcome: [email protected]